First published: Fri Dec 01 2017(Updated: )
The GPU driver of Mate 9 Huawei smart phones with software before MHA-AL00B 8.0.0.334(C00) and Mate 9 Pro Huawei smart phones with software before LON-AL00B 8.0.0.334(C00) has a memory double free vulnerability. An attacker tricks a user into installing a malicious application, and the application can call special API, which triggers double free and causes a system crash or arbitrary code execution.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei Mate 9 Firmware | <mha-al00b_8.0.0.334\(c00\) | |
Huawei Mate 9 | ||
Huawei Mate 9 Pro Firmware | <lon-al00b_8.0.0.334\(c00\) | |
Huawei Mate 9 Pro |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2017-15316.
The severity of CVE-2017-15316 is critical, with a severity value of 7.8.
Mate 9 Huawei smart phones with software before MHA-AL00B 8.0.0.334(C00) and Mate 9 Pro Huawei smart phones with software before LON-AL00B 8.0.0.334(C00) are affected by CVE-2017-15316.
An attacker can exploit CVE-2017-15316 by tricking a user into installing a malicious application, which can lead to a memory double free vulnerability.
Yes, Huawei has released a security advisory with the fix for CVE-2017-15316. Please refer to the provided reference for more information.